Skip to main content
EPSS 0.2%top 95%

Red Hat Security Advisory: RHOAI 2.16.4 - Red Hat OpenShift AI

0
High
Published: 03/25/2026 (03/25/2026, 12:32:51 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

Release of RHOAI 2.16.4 provides these changes:

Affected software

Affected versions
>=2.14.0 <=2.14.*>=2.16.0 <=2.16.*=1.5=1.3Red HatRed Hat OpenShift AIRed Hat OpenShift AI 2.16amd64registry.redhat.io/rhoai/odh-codeflare-operator-rhel8@sha256:b68b73951beeabe942be43f65e778ff98e1cdfc6fdb4b052794f0cd4b191b819_amd64OpenShift API for Data ProtectionOpenShift API for Data Protection 1.5registry.redhat.io/oadp/oadp-hypershift-velero-plugin-rhel9@sha256:2c9332fa68acce79d7defcec12c651d6d331a32208f4325e798cf37971a35fed_amd64Red Hat OpenStack PlatformRed Hat OpenStack Platform 16.2registry.redhat.io/rhosp-rhel8/osp-director-agent@sha256:26005fbf7d5e2b62db9368a3ec4858c22c653e45abe328feda7dc26e3039b355_amd64Red Hat OpenStack Platform 17.1registry.redhat.io/rhosp-rhel9/osp-director-agent@sha256:a618bbff08e2c106afa08a7daf100b51ac7ae53fe932fa2611087df303cc79f0_amd64Red Hat Advanced Cluster SecurityRed Hat Advanced Cluster Security 4.7registry.redhat.io/advanced-cluster-security/rhacs-central-db-rhel8@sha256:6ec722f4a9558cd2c409811b2da56a0af971a7f586a8d3c7a1ae1f47e25c7fb5_amd64Network Observability (NETOBSERV)Network Observability (NETOBSERV) 1.11.0registry.redhat.io/network-observability/network-observability-flowlogs-pipeline-rhel9@sha256:9e495db6e28bb6e38b263557d303081ed3199039dc1e7d18c704be8b64d8dd18_amd64Red Hat OpenShift Dev Spaces (RHOSDS)Red Hat OpenShift Dev Spaces (RHOSDS) 3.26registry.redhat.io/devspaces/code-rhel9@sha256:772af8d40b674ce306850d3ecf2b70b39bdceaf9e045a2db9299c0dd8bd5e6b5_amd64OpenShift API for Data Protection 1.3registry.redhat.io/oadp/oadp-cli-binaries-rhel9@sha256:56a93ad53df1c0445b3fee293ab42caa375f88b72872d8fb844efeb114869eaa_amd64Red Hat Advanced Cluster Management for KubernetesRed Hat Advanced Cluster Management for Kubernetes 2.14registry.redhat.io/rhacm2/lighthouse-agent-rhel9@sha256:bbe086814cc2fe9e53699ff23705479b493a62f9521b5f2664fcdb97dd5705a9_amd64Red Hat Openshift Data FoundationRed Hat Openshift Data Foundation 4.22registry.redhat.io/odf4/cephcsi-rhel9@sha256:05df2bcbadb214e4873082f282ef013565f04f24dce406d3802288d6ad574741_amd64Red Hat multicluster global hubRed Hat multicluster global hub 1.4.3registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:242aee0257e823b6537c263d99138a0e801a1d586f211c45290e64722c18acf4_amd64Network Observability (NETOBSERV) 1.11.1Red Hat multicluster global hub 1.4.2registry.redhat.io/odf4/odf-dependencies-operator-bundle@sha256:9361befe3f0fe01ff32ecf2d7de1a3f6ffac4b43a13e654a276798c196e0131b_amd64Network Observability (NETOBSERV) 1.11.2Multicluster Global HubMulticluster Global Hub 1.4.5Red Hat multicluster global hub 1.5.3registry.redhat.io/multicluster-globalhub/multicluster-globalhub-grafana-rhel9@sha256:02d64a5e1254f66b6daae1188688d5289acb7832819005de439285ba1dc68f20_amd64

Weaknesses

CWE-279CWE-770CWE-1050CWE-409CWE-1286CWE-367CWE-1241CWE-1284CWE-551CWE-131CWE-303CWE-78CWE-22CWE-179CWE-674CWE-73CWE-1333CWE-248CWE-1287CWE-776CWE-59CWE-347CWE-436CWE-79CWE-1321CWE-771CWE-405CWE-190CWE-276CWE-88CWE-20CWE-400CWE-909CWE-918CWE-476CWE-354CWE-606CWE-524CWE-1289CWE-772CWE-281CWE-358CWE-426CWE-601CWE-427CWE-295CWE-681CWE-197CWE-158CWE-362CWE-1341CWE-1046CWE-807CWE-241

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/14/2026, 21:40:25 UTC

Technical Analysis

CVE-2024-25621 is a local privilege escalation vulnerability in containerd caused by overly permissive default directory permissions. Local users on the host can access the metadata store, content store, and Kubernetes local volumes, which may contain setuid binaries, enabling privilege escalation. The vulnerability affects several Red Hat products that ship containerd, including OpenShift API for Data Protection and Advanced Cluster Management for Kubernetes. The issue can be mitigated by restricting permissions on containerd directories or running containerd in rootless mode. Red Hat has provided advisories and guidance but the patch status is not explicitly confirmed in the advisory content provided.

Potential Impact

Local users with access to the host can exploit overly broad permissions to read and modify containerd metadata and content stores, including Kubernetes local volumes. This can lead to privilege escalation on the host system by leveraging setuid binaries present in the volumes. The vulnerability compromises confidentiality and integrity with high impact, while availability impact is low to none. No active exploitation in the wild has been reported.

Mitigation Recommendations

Administrators should manually restrict permissions on the following directories to remove group and world access: /var/lib/containerd, /run/containerd/io.containerd.grpc.v1.cri, and /run/containerd/io.containerd.sandbox.controller.v1.shim by setting permissions to 700. Alternatively, running containerd in rootless mode mitigates the issue. Check the Red Hat advisory for updates on official patches or fixes. Patch status is not explicitly confirmed; verify with the vendor advisory for current remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:5807
Cve Count
19
Additional Cves
["CVE-2025-6193","CVE-2025-12060","CVE-2025-12638","CVE-2025-12816","CVE-2025-61726","CVE-2025-61729","CVE-2025-66031","CVE-2025-66418","CVE-2025-66626","CVE-2025-68156","CVE-2025-69873","CVE-2026-1526","CVE-2026-1528","CVE-2026-2229","CVE-2026-25223","CVE-2026-25639","CVE-2026-29074","CVE-2026-32141"]

Threat ID: 6a160964e29bf47b506290f5

Added to database: 05/26/2026, 20:58:12 UTC

Last enriched: 08/14/2026, 21:40:25 UTC

Last updated: 09/15/2026, 01:48:53 UTC

Views: 137

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:25127https://access.redhat.com/security/cve/CVE-2024-25621https://access.redhat.com/security/cve/CVE-2025-61726https://access.redhat.com/security/cve/CVE-2025-61728https://access.redhat.com/security/cve/CVE-2025-61729https://access.redhat.com/security/cve/CVE-2025-68121https://access.redhat.com/security/cve/CVE-2025-68151https://access.redhat.com/security/cve/CVE-2026-21441https://access.redhat.com/security/cve/CVE-2026-25679https://access.redhat.com/security/cve/CVE-2026-26017https://access.redhat.com/security/cve/CVE-2026-26018https://access.redhat.com/security/cve/CVE-2026-32280https://access.redhat.com/security/cve/CVE-2026-32936https://access.redhat.com/security/cve/CVE-2026-33186https://access.redhat.com/security/cve/CVE-2026-34986https://access.redhat.com/security/cve/CVE-2026-35579https://access.redhat.com/security/updates/classification/Canonical URLhttps://access.redhat.com/errata/RHSA-2026:5807https://access.redhat.com/security/cve/CVE-2025-12060https://access.redhat.com/security/cve/CVE-2025-12638https://access.redhat.com/security/cve/CVE-2025-12816https://access.redhat.com/security/cve/CVE-2025-6193https://access.redhat.com/security/cve/CVE-2025-66031https://access.redhat.com/security/cve/CVE-2025-66418https://access.redhat.com/security/cve/CVE-2025-66626https://access.redhat.com/security/cve/CVE-2025-68156https://access.redhat.com/security/cve/CVE-2025-69873https://access.redhat.com/security/cve/CVE-2026-1526https://access.redhat.com/security/cve/CVE-2026-1528https://access.redhat.com/security/cve/CVE-2026-2229https://access.redhat.com/security/cve/CVE-2026-25223https://access.redhat.com/security/cve/CVE-2026-25639https://access.redhat.com/security/cve/CVE-2026-29074https://access.redhat.com/security/cve/CVE-2026-32141https://access.redhat.com/errata/RHSA-2026:2343https://access.redhat.com/security/cve/CVE-2025-52881https://access.redhat.com/security/cve/CVE-2025-58183https://docs.redhat.com/en/documentation/openshift_container_platform/latest/html/backup_and_restore/oadp-application-backup-and-restoreCanonical URLhttps://access.redhat.com/errata/RHSA-2026:2456https://access.redhat.com/documentation/en-us/red_hat_openshift_dev_spaces/3.26/html/administration_guide/installing-devspaceshttps://access.redhat.com/security/cve/CVE-2025-15284https://access.redhat.com/security/cve/CVE-2025-64756https://access.redhat.com/security/cve/CVE-2025-65945https://access.redhat.com/security/cve/CVE-2025-66471https://access.redhat.com/security/cve/CVE-2025-66490https://access.redhat.com/security/cve/CVE-2026-22029Canonical URLhttps://access.redhat.com/errata/RHSA-2026:2900https://access.redhat.com/security/cve/CVE-2025-13465https://access.redhat.com/security/cve/CVE-2025-64329https://access.redhat.com/security/cve/CVE-2025-66506https://access.redhat.com/security/cve/CVE-2026-23745https://access.redhat.com/security/cve/CVE-2026-24049https://access.redhat.com/security/cve/CVE-2026-24842https://docs.openshift.com/container-platform/latest/observability/network_observability/network-observability-operator-release-notes.htmlCanonical URLhttps://access.redhat.com/errata/RHSA-2026:37387https://access.redhat.com/security/cve/CVE-2024-40635https://access.redhat.com/security/cve/CVE-2024-45310https://access.redhat.com/security/cve/CVE-2025-21613https://access.redhat.com/security/cve/CVE-2025-21614https://access.redhat.com/security/cve/CVE-2025-22870https://access.redhat.com/security/cve/CVE-2025-47911https://access.redhat.com/security/cve/CVE-2025-54410https://access.redhat.com/security/cve/CVE-2025-58058https://access.redhat.com/security/cve/CVE-2025-8766https://access.redhat.com/security/cve/CVE-2026-22772https://access.redhat.com/security/cve/CVE-2026-23831https://access.redhat.com/security/cve/CVE-2026-24117https://access.redhat.com/security/cve/CVE-2026-25680https://access.redhat.com/security/cve/CVE-2026-25681https://access.redhat.com/security/cve/CVE-2026-25934https://access.redhat.com/errata/RHSA-2025:23248https://access.redhat.com/security/cve/CVE-2025-47907https://access.redhat.com/security/cve/CVE-2025-59375https://access.redhat.com/security/cve/CVE-2025-6965https://access.redhat.com/security/cve/CVE-2025-9648https://docs.redhat.com/en/documentation/red_hat_advanced_cluster_security_for_kubernetes/4.7/html-single/release_notes/index#about-this-release-479_release-notes-47Canonical URLhttps://access.redhat.com/errata/RHSA-2025:23644Canonical URLhttps://access.redhat.com/errata/RHSA-2026:3122https://access.redhat.com/security/cve/CVE-2025-47913https://catalog.redhat.com/software/containers/searchCanonical URLhttps://access.redhat.com/errata/RHSA-2025:22955Canonical URLhttps://access.redhat.com/errata/RHSA-2025:23428Canonical URLhttps://access.redhat.com/errata/RHSA-2026:51033https://access.redhat.com/security/cve/CVE-2026-27136https://access.redhat.com/security/cve/CVE-2026-32281https://access.redhat.com/security/cve/CVE-2026-32282https://access.redhat.com/security/cve/CVE-2026-33747https://access.redhat.com/security/cve/CVE-2026-33748https://access.redhat.com/security/cve/CVE-2026-33810https://access.redhat.com/security/cve/CVE-2026-33811https://access.redhat.com/security/cve/CVE-2026-39820https://access.redhat.com/security/cve/CVE-2026-39821Search on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses